Secure AI authentication is implemented for selectable environments with a selectable combination of ML models processing selectable input credentials, e.g., biometric and/or non-biometric credentials, such as a key associated with a secure model, user location information, a user gesture credential, and/or a user movement pattern credential. ML models may be selectively applied in serial or parallel in a selected authorization procedure. ML model applicability may vary based on one or more parameters, such as time of day, or one or more detected input credentials, such as user gestures, secure model keys, or biometric voice or face recognition. For example, AI authorization (e.g., for biometric credentials) augmented with an ultra-wideband (UWB) communication protocol provides robust user authentication via a native cryptographic exchange and accurate user location credentials for proximity and geo-fenced confirmation of other user credentials, such as biometric credentials, thereby preventing false positives by spoofing.
Legal claims defining the scope of protection, as filed with the USPTO.
retrieving a secure token from secure storage in the secure component; wirelessly providing the secure token to a host device performing authentication of a user; in response to authentication of the user by the host device, receiving a user credential synchronization request from the host device; providing a key manifest to the host device in response to the user credential synchronization request; in response to a determination the key manifest is unsynchronized based on the absence of one or more user credentials, receiving the one or more absent user credentials; and storing the received one or more absent user credentials in the secure storage to synchronize the user credentials with at least one external user credential store. . A method executed by a secure component, comprising:
claim 1 . The method of, wherein the secure component comprises a smart card.
claim 1 providing an additional user credential to the host device performing the user authentication. . The method of, further comprising:
claim 1 . The method of, wherein the one or more absent user credentials is determined by the host device.
claim 1 . The method of, wherein the one or more absent user credentials is determined by a server and indicated to the host device.
claim 1 . The method of, wherein the secure token is provided to the host device by the secure component using near field communication (NFC) or ultra-wideband (UWB) communication.
claim 1 receiving a request for user credential recovery; and participating in the user credential recovery by recovering user credentials from the secure storage according to a user credential recovery configuration. . The method of, further comprising:
claim 7 receiving the user credential recovery configuration; and indicating multi-factor authentication information for recovery of user credentials. . The method of, further comprising:
wirelessly receiving a secure token from secure storage in an external secure component; performing authentication of a user based on the secure token; in response to authentication of the user, transmitting a user credential synchronization request to the secure component; receiving a key manifest from the secure component in response to the user credential synchronization request; and in response to a determination the key manifest is unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the secure component for storage in the secure storage to synchronize the user credentials in the secure component with a user credential store. . A method executed by a host device, comprising:
claim 9 . The method of, wherein the secure component comprises a smart card.
claim 9 receiving an additional user credential for the user authentication. . The method of, further comprising:
claim 9 . The method of, wherein the user credential store is managed by at least one of the host device or a server.
claim 9 . The method of, wherein the host device receives the secure token from the secure component using near field communication (NFC) or ultra-wideband (UWB) communication.
claim 9 transmitting a request for user credential recovery to the secure component; and participating in a user credential recovery by recovering user credentials from the secure storage according to a user credential recovery configuration. . The method of, further comprising:
claim 14 transmitting the user credential recovery configuration to the secure component, wherein the user credential recovery configuration indicates multi-factor authentication information for recovery of user credentials. . The method of, further comprising:
claim 15 transmitting a user credential synchronization configuration to the secure component for responding to the user credential synchronization, wherein the user credential synchronization configuration indicates what information is synchronized, synchronization conditions, and synchronization security. . The method of, further comprising:
receiving a user credential synchronization request comprising a key manifest for a secure component from a host device in response to a user credential synchronization request provided by the host device to the secure component following authentication of a secure token received by the host device from the secure component; determining whether the key manifest provided by the secure component is synchronized with user credentials in a user credential store managed by the server; and in response to a determination the key manifest is unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the host device for transmission to the secure component to synchronize the user credentials in the secure component with the user credential store managed by the server. . A method executed by a server, comprising:
claim 17 transmitting a request for user credential recovery; and participating in a user credential recovery by recovering user credentials from the secure component according to a user credential recovery configuration. . The method of, further comprising:
claim 18 transmitting the user credential recovery configuration to the host device for transmission to the secure component, wherein the user credential recovery configuration indicates multi-factor authentication information for recovery of user credentials. . The method of, further comprising:
claim 17 transmitting a user credential synchronization configuration to the host device for transmission to the secure component for responding to the user credential synchronization, wherein the user credential synchronization configuration indicates what information is synchronized, synchronization conditions, and synchronization security. . The method of, further comprising:
Complete technical specification and implementation details from the patent document.
“Authentication” is the act of proving an assertion such as the identity of a computer system user. In contrast with identification, which is the act of indicating identity, authentication is the process of verifying that identity. Various techniques are used in computer systems to perform authentication of a user, such as by receiving a passcode provided by the user, detecting a biometric factor associated with the user, exchanging a communication with a device of the user, etc. The received factor of the user may be compared to a known factor of the user to authenticate the user. “Single-factor” authentication may be performed, which uses a single received aspect (e.g., a passcode) to authenticate the user, or “multi-factor” authentication may be performed, which uses multiple received aspects (e.g., passcode and fingerprint) to authenticate the user.
This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
Non-contact authentication for key recovery and platform security provisioning is disclosed herein. Access credentials are backed up to and recovered from a user device, such as a smart card, utilized as a secondary root of trust. Automatic, secure backup and storage of security related information (e.g., user authentication keys, user credentials, crypto tokens, disc encryption recovery key keys, etc.) occurs wirelessly onto one or more personal accessories, such as a secure near-field communication (NFC) card or a mobile embedded secure component. Access to store and retrieve can be further enhanced with geo location presence detection provided via a wireless interface.
In a further aspect, a secure information backup/synchronization and recovery service provides an interface for an administrator/user to specify a backup procedure and a recovery procedure to access the backed up information. Information to be backed up to secure storage in a user device may be configured, such as trusted platform module (TPM), disc encryption recovery key, file encryption, and/or account credentials. A user can authenticate during a recovery procedure to retrieve keys backed up on a user device via any configured method. Automated backup/synchronization is triggered by one or more configured conditions, such as successful authentication, resulting in automated backup of all configured secure access credentials to one or more designated destinations. Credential backup synchronization to a user device may be triggered periodically or aperiodically, for example, by successful user authentication during a login procedure.
In one aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a user device, comprises: retrieving a secure token from secure storage in the secure component; wirelessly providing the secure token to a host device performing user authentication; if the user is authenticated by the host device, receiving a user credential synchronization request from the host device; providing a key manifest to the host device in response to the user credential synchronization request; if the key manifest is determined to be unsynchronized based on the absence of one or more user credentials, receiving the one or more absent user credentials; and storing the received one or more absent user credentials in the secure storage to synchronize the user credentials with at least one external user credential store.
According to another aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a host device, comprises: wirelessly receiving a secure token from secure storage in an external secure component; performing user authentication based on the secure token; if the user is authenticated, transmitting a user credential synchronization request to the secure component; receiving a key manifest from the secure component in response to the user credential synchronization request; if the key manifest is determined to be unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the secure component for storage in the secure storage to synchronize the user credentials in the secure component with a user credential store.
According to still another aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a server, comprises: receiving a user credential synchronization request comprising a key manifest for a secure component from a host device in response to a user credential synchronization request provided by the host device to the secure component following authentication of a secure token received by the host device from the secure component; determining whether the key manifest provided by the secure component is synchronized with user credentials in a user credential store managed by the server; and if the key manifest is determined to be unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the host device for transmission to the secure component to synchronize the user credentials in the secure component with the user credential store managed by the server.
Further features and advantages of the embodiments, as well as the structure and operation of various embodiments, are described in detail below with reference to the accompanying drawings. It is noted that the claimed subject matter is not limited to the specific embodiments described herein. Such embodiments are presented herein for illustrative purposes only. Additional embodiments will be apparent to persons skilled in the relevant art(s) based on the teachings contained herein.
The subject matter of the present application will now be described with reference to the accompanying drawings. In the drawings, like reference numbers indicate identical or functionally similar elements. Additionally, the left-most digit(s) of a reference number identifies the drawing in which the reference number first appears.
The following detailed description discloses numerous example embodiments. The scope of the present patent application is not limited to the disclosed embodiments, but also encompasses combinations of the disclosed embodiments, as well as modifications to the disclosed embodiments. It is noted that any section/subsection headings provided herein are not intended to be limiting. Embodiments are described throughout this document, and any type of embodiment may be included under any section/subsection. Furthermore, embodiments disclosed in any section/subsection may be combined with any other embodiments described in the same section/subsection and/or a different section/subsection in any manner.
Various techniques are used in computer systems to perform authentication of a user, such as receiving a passcode provided by the user, a physical biometric factor associated with the user (e.g., a fingerprint, an image such as a facial scan), a behavior-related biometric factor associated with the user (e.g., keyboard dynamics, gait recognition, hand gestures), a device of the user (e.g., an ID card, a security token) etc. The received factor of the user is compared to a known factor of the user to authenticate the user. Single-factor authentication may be performed, which uses a single received factor to authenticate the user, or multi-factor authentication may be performed, which uses multiple received factors to authenticate the user.
Storing recovery tokens remotely (e.g., in the cloud) requires a secure connection in order to retrieve a secure challenge and apply its output to a local machine. Keeping authentication tokens only in the cloud may also utilize a VPN (virtual private network) connection to an IT (information technology) cloud-based application and user verification with additional inputs. For example, a full volume/disc encryption component can go into failsafe mode where it needs to be presented with encryption keys to unlock a local machine. A user has to manually enter a backed up encryption key or go to an information technology (IT) service to have the machine reprovisioned. In contrast, non-contact authentication for key recovery and platform security provisioning provides automated entry of the encryption keys to restore the system state. Automated backup/synchronization and recovery of keys in one or more user devices saves time and money by supporting swift access and recovery.
Embodiments described herein enable non-contact authentication for key recovery and platform security provisioning. Access credentials are backed up to and recovered from a user device, such as a smart card, utilized as a secondary root of trust. Automatic, secure backup and storage of user authentication keys, crypto tokens, disc encryption recovery keys, etc. occurs wirelessly onto one or more personal accessories, such as a secure near-field communication (NFC) card or a mobile embedded secure component. For example, NFC enabled devices can auto-save secure information in secure storage vaults that are already part of the NFC subsystem when they successfully ‘tap to’ authenticate to access a host computing system. Access to store and retrieve can be further enhanced with geo location presence detection, e.g., using ultra-wideband (UWB). Credentials can be recovered from secure storage in a user device via a wireless interface, such as NFC or UWB.
A secure information backup/synchronization and recovery service provides an interface for an administrator/user to specify a backup procedure (e.g., indicating what secure key/credential information to backup, when, where, and how) and a recovery procedure to access the backed up information. Information to be backed up to secure storage in a user device may be configured, such as trusted platform module (TPM), disc encryption recovery key, file encryption, and/or account credentials. A user can authenticate during a recovery procedure to retrieve keys backed up on a user device via any configured method, such as password, geofence, trusted third party, etc. Automated backup/synchronization is triggered by one or more configured conditions, such as successful authentication, resulting in automated backup of all configured secure access credentials to one or more designated destinations (e.g., one or more secure user devices or other secure locations). Credential backup synchronization to a user device may be triggered periodically or aperiodically, for example, by successful user authentication during a login procedure. For example, when a user logs in to a host device with an NFC-enabled smart card (SC), designated keys (e.g., disc encryption recovery key) are backed up into a secure component (SE) in the NFC-enabled SC and/or one or more other secure locations indicated to the service.
In one aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a user device, comprises: retrieving a secure token from secure storage in the secure component; wirelessly providing the secure token to a host device performing user authentication; if the user is authenticated by the host device, receiving a user credential synchronization backup request from the host device; providing a key manifest to the host device in response to the user credential synchronization request; if the key manifest is determined to be unsynchronized based on the absence of one or more user credentials, receiving the one or more absent user credentials; and storing the received one or more absent user credentials in the secure storage to synchronize the user credentials with at least one external user credential store. In this manner, missing (absent) user credentials are backed up in the secure storage, thereby synchronizing the user device with the external user credential store (e.g., a user terminal, a server, or other credential store), thereby providing for redundant storage.
According to another aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a host device, comprises: wirelessly receiving a secure token from secure storage in an external secure component; performing user authentication based on the secure token; if the user is authenticated, transmitting a user credential synchronization backup request to the secure component; receiving a key manifest from the secure component in response to the user credential synchronization request; if the key manifest is determined to be unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the secure component for storage in the secure storage to synchronize the user credentials in the secure component with a user credential store.
According to still another aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a server, comprises: receiving a user credential synchronization request comprising a key manifest for a secure component from a host device in response to a user credential synchronization request provided by the host device to the secure component following authentication of a secure token received by the host device from the secure component; determining whether the key manifest provided by the secure component is synchronized with user credentials in a user credential store managed by the server; and if the key manifest is determined to be unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the host device for transmission to the secure component to synchronize the user credentials in the secure component with the user credential store managed by the server.
1 6 FIGS.- 1 FIG. 1 FIG. 100 100 104 106 110 108 104 112 114 116 118 120 106 130 132 134 136 138 140 146 148 114 114 114 134 134 134 110 150 152 154 154 162 a b a b These and further embodiments may be implemented in various ways. To help illustrate such embodiments,are described as follows. In particular,shows a block diagram of an example systemconfigured for non-contact authentication for key recovery and platform security provisioning, in accordance with embodiments. Systemincludes a user device, a user terminal, and one or more servers, which are communicatively coupled by one or more networks. User deviceincludes one or more sensor(s), one or more transceivers, and a secure componentthat includes a secure processorand secure storage. Terminal device, also referred to herein as “host device,” includes one or more central processing units (CPUs), one or more sensors, one or more transceivers, a secure componentthat includes a secure processorand secure storage, one or more user accessible environments, and a security manager. Transceiver(s)includes a UWB interfaceand an NFC interface. Transceiver(s)includes a UWB interfaceand an NFC interface. Each server of server(s)includes a security service, a secure componentthat includes a secure processorand secure storage, and one or more user accessible environments. Dashed lines indicate components or subcomponents may or may not be present in a variety of implementations. These features ofare described in further detail as follows.
104 104 100 104 User devicecomprises one or more passive or active devices that transmit one or more user authorization, identification, or access credentials, such as a tag, a badge, a cellular phone, a beacon, a fob, a watch, a pen, a wearable device, etc. Note that any number of user devicesmay be present in system, including tens, hundreds, thousands, millions, and even greater numbers of user devices.
112 112 104 Sensor(s)include a wide variety of sensors used to detect information pertaining to one or more user credentials, such as a camera, a microphone, a fingerprint reader, an accelerometer, a global positioning system (GPS) sensor, a presence detector (e.g., RADAR), and so on. Sensor(s), as indicated by dashed lines, may or may not be present in one or more types of user devices, such as a cellular/mobile phone, smart card, smart watch, etc.
114 164 104 106 166 104 110 114 114 104 114 104 a b b Transceiver(s)provide wireless and/or wired communications including a communicationbetween user deviceand user terminaland/or a communicationbetween user deviceand server(s). Such communications may be conducted over a wired or wireless network interface, such as, for example, one or more of the following wired or wireless interfaces: a UWB interface, a near field communication (NFC) interface, an IEEE 802.11 wireless LAN (WLAN) wireless interface (e.g., a WiFi interface), a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth™ interface, etc. In an example, user deviceis a UWB-enabled device. NFC interfacecan be, for example, a listener. Further examples of network interfaces that may be incorporated in user deviceare described elsewhere herein.
124 102 106 106 148 102 104 In some example implementations, UWB provides useful metadata as contextual inputs for user credentials, such as time of flight and angle of arrival, which may be used as user location credentials to verify a location or proximity of userrelative to user terminal, allowing user terminal(e.g., security manager) to geofence around userand user device.
164 166 124 122 122 122 122 126 128 128 104 104 102 106 116 114 124 122 122 118 b a b b b a Communications,may pertain, for example, to user credentials(e.g., password, face recognition, voice recognition), secure keys, key manifest, authentication/authorization determinations, sensed information, a secure information (e.g., credential/key) backup operation (e.g., to provide a key manifest, receive missing keys, receive configuration,), a secure information (e.g., credential/key) recovery operation (e.g., to receive a recovery configuration, receive a recovery request, provide recovery information), etc. In some examples, secure user devicecaptures (e.g., samples or detects) biometric or other information. In some examples, secure user deviceprovides (e.g., and may collect) user credentials (e.g., fingerprint or other biometric or no-biometric information) for userto user terminalfor user authentication, backup operations, and/or recovery operations. For example, secure componentmay cause a transceiver or transceiver(s)to send or receive user credentials, keys, and/or key manifestbased on executable code associated with one or more operations executed by secure processor.
116 116 104 116 116 118 120 116 118 Secure componentrepresents a secure platform module, such as a trusted platform module (TPM). Secure componentprovides an isolated secure environment not affected by other software (e.g., malware) that may exist on user deviceoutside of secure component. Secure componentincludes secure processorand secure storage. Secure componentincludes a secure operating system (OS) (not shown) executed by secure processor.
120 122 124 126 128 122 122 122 122 122 122 172 106 164 110 108 166 122 172 a b a b b b Secure storageincludes any data an administrator/user seeks to protect, such as key database, user credentials, backup configuration, recovery configuration, etc. Key databaseincludes key manifestand keys. Key manifestindicates each key among keys. Keysare used to generate a secure tokento be transmitted to user terminalin communicationand/or to server(s)via network(s)in communication. Keysinclude, for example, public keys, private keys, cloud keys, and/or secure shell (SSH) keys. Secure tokencan be, for example, a wrapped version of a data encryption key protected by a user credential, such as a user password.
118 120 124 122 122 126 128 118 120 b a Secure processoris a tamper-resistant processor that protects secure assets stored in secure storage, such as a root of trust, sensitive data, such as user credentials, keys, key manifest, certificates, a disc encryption recovery key, applications, backup/synchronization configuration, recovery configuration, etc. against attacks attempting to use software or hardware. Secure processorprocesses executable code (e.g., programs or applications) to perform operations that access, modify, send, receive, and store data in secure storage.
118 120 120 118 122 106 110 104 106 110 120 126 128 124 a Secure processorexecutes operations to backup/synchronize secure information stored in secure storageand to recover secure information stored in secure storage. Secure processor, for example, provides key manifestto user terminaland/or to server(s)to determine whether user deviceis synchronized with user terminaland/or server(s)in terms of secure information stored in secure storage. The secure information subject to backup and recovery can be fixed or variable based on configuration. For example, backup configurationcan indicate which information is backed up and conditions for backing up, such as following successful authentication and/or additional user credentials. For example, recovery configurationcan indicate which information is recoverable and conditions for recovery, such as user credentials. User credentialsinclude one or more types of credentials, such as biometric, non-biometric, location, non-location, contactless, contact, and so on. For example, user credentials can include user location credential(s), such as three dimensional (3D) position, geo-location, and/or RADAR, and/or non-location credential(s), such as face recognition, voice recognition, gesture(s), movement pattern(s), key(s), and/or time and date.
102 106 102 104 104 106 102 106 104 106 104 172 122 124 106 104 102 102 104 106 104 102 104 122 120 106 106 122 120 106 102 106 122 120 110 122 120 106 102 110 106 104 120 104 106 110 102 104 b a a a a In an example, userapproaches user terminal, which may be a computing device such as a tablet. Useris carrying user device, which may be a smart card. User taps user deviceon user terminalto authenticate and log userinto user terminal. User deviceand user terminalcommunicate messages pertaining to authentication, for example, using NFC. User deviceprovides secure tokencomprising one or more keyssecured by a user password in user credentials. User terminalmay transmit a user credential synchronization request to user deviceas a request that userenter a secondary credential such as a password to confirm the useris associated with user device. In the background, user terminalrequests that user deviceengage in secure information synchronization, e.g., following successful authentication of user. User deviceprovides key manifest(e.g., and/or other list of information secured in secure storage) to user terminal. User terminalcompares key manifest(e.g., and/or other list of information secured in secure storage) with secure information stored by user terminalfor user. User terminalmay provide the key manifest(e.g., and/or other list of information secured in secure storage) to server(s), which may (e.g., additionally or alternatively) compare key manifest(e.g., and/or other list of information secured in secure storage) with secure information stored by user terminalfor user. Server(s)and/or user terminalprovide any absent secure information (e.g., keys, user credentials) to user device(e.g., in encrypted form) for storage in secure storageto synchronize user devicewith user terminaland/or server(s)regarding storage of secure information for authentication of user. Synchronization supports continuing ability to use user devicefor user authentication and swift user credential recovery.
104 166 170 150 110 102 162 104 110 108 150 110 148 106 User devicecan be configured to, alternatively or additionally, communicate via communicationsand communicationswith security servicein server(s), which can manage user authentication for userand other users to access user accessible environment(s). For example, user devicecan be a cellular phone configured to communicate with server(s)via an internet connection carried over a cellular communication network. Security servicein server(s)may be configured similarly to security managerin user terminal.
106 106 106 146 146 106 102 148 146 106 106 146 106 106 106 130 132 134 136 138 140 146 148 106 100 104 User terminalis any type of device utilizing user authentication, e.g., for user identification or authorization. User terminalis fixed or mobile, such as a mobile phone or other mobile computing environment, a desktop computer, an operating system, a network environment, a building, an automobile, and so on. User terminalprovides access to one or more user accessible environments. User accessible environment(s)comprise one or more environments in user terminalthat usermay be granted access to based on user authentication performed by security manager. An example of user accessible environmentis the operating system of user terminal, building access, etc. In some examples, user terminalis a computing system permitting authorized users to access user accessible environments, such as a computing device, a computing network, a computing service (e.g., cloud service), computing resources, data, etc. In some examples, user terminalis configured to pair or not pair an input, output, or peripheral device (e.g., pen, mouse, keyboard, headset) with a computing system based on a user determination. In some examples, user terminalis a financial or payment system permitting authorized user to access user records, make or receive payments, etc. User terminalincludes one or more processors, one or more sensor(s), one or more transceivers, a secure componentwith a secure processorand secure storage, one or more user accessible environments, and a security manager. Note that any number of user terminalsmay be present in system, including tens, hundreds, thousands, millions, and even greater numbers of user devices.
130 610 130 132 134 6 FIG. Processor(s)is/are as described inas processor. Processor(s)execute an operating system (not shown) and applications, for example, to perform detection using sensor(s)and communication via transceiver(s).
132 Sensor(s)include a wide variety of sensors used to detect information pertaining to one or more user credentials, such as a camera, a microphone, a fingerprint reader, an accelerometer, a global positioning system (GPS) sensor, a presence detector (e.g., RADAR), and so on.
134 164 104 106 168 106 108 134 134 106 104 134 106 104 a b b Transceiver(s)provide wireless and/or wired communication, for example, communicationbetween user deviceand user terminaland/or communicationbetween user terminaland network(s). Communication may be provided by a wired or wireless network interface, such as, for example, one or more of the following wired or wireless interfaces: a UWB interface, an IEEE 802.11 wireless LAN (WLAN) wireless interface (e.g., a WiFi interface), a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth™ interface, a near field communication (NFC) interface, etc. For example, user terminaland user devicemay be UWB-enabled. NFC interfacecan be, for example, a reader/poller. Further examples of network interfaces that may be incorporated in user terminaland user deviceare described elsewhere herein.
164 168 124 144 160 122 142 158 122 142 158 122 142 158 122 142 158 126 148 128 148 128 148 104 106 104 102 106 116 114 124 122 122 118 b b b a a a a a a b b b d f f b a Communications,may pertain, for example, to user credentials//(e.g., password, face recognition, voice recognition), secure keys//, key manifest//, authentication/authorization determinations, sensed information, a secure information (e.g., credential/key) backup operation (e.g., to receive or provide a key manifest//, receive or provide missing keys//, receive or provide configuration/,/), a secure information (e.g., credential/key) recovery operation (e.g., to receive a recovery configuration/, receive a recovery request, provide recovery information), etc. In various examples, secure user deviceand/or user terminalcaptures (e.g., samples or detects) biometric or other information. In some examples, (e.g., UWB-enabled and/or NFC-enabled) secure user deviceprovides (e.g., and may collect) user credentials (e.g., fingerprint or other biometric or no-biometric information) for userto user terminalfor user authentication, backup operations, and/or recovery operations. For example, secure componentmay cause transceiver(s)to send or receive user credentials, keys, and/or key manifestbased on executable code associated with one or more operations executed by secure processor.
136 136 106 136 136 138 140 136 138 Secure componentrepresents a secure platform module, such as a trusted platform module (TPM). Secure componentprovides an isolated secure environment not affected by other software (e.g., malware) that may exist on user terminaloutside of secure component. Secure componentincludes secure processorand secure storage. Secure componentincludes a secure operating system (OS) (not shown) executed by secure processor.
140 142 144 142 142 142 142 142 142 104 122 172 106 164 110 108 166 142 140 120 a b a b b b b Secure storageincludes any data an administrator/user seeks to protect, such as key database, user credentials, etc. Key databaseincludes key manifestand keys. Key manifestindicates each key among keys. Keysmay be provided to user deviceas keysto use to generate secure tokento be transmitted to user terminalin communicationand/or to server(s)via network(s)in communication. Keysinclude, for example, one or more of public keys, private keys, cloud keys, and/or secure shell (SSH) keys. The contents of secure storagemay be synchronized to and recovered from secure storage.
138 140 144 142 142 138 140 b a Secure processoris a tamper-resistant processor that protects secure assets stored in secure storage, such as a root of trust, sensitive data, such as user credentials, keys, key manifest, certificates, disc encryption recovery key, applications, etc. against attacks attempting to use software or hardware. Secure processorprocesses executable code (e.g., programs or applications) to perform operations that access, modify, send, receive, and store data in secure storage.
138 148 148 104 126 128 140 120 120 138 122 104 104 106 110 120 140 148 148 144 d f a d f Secure processorexecutes operations to provide backup configurationand recovery configurationto user deviceto store as backup configurationand recovery configuration, respectively, to backup/synchronize secure information stored in secure storagewith secure information stored in secure storage, and to recover secure information stored in secure storage. Secure processor, for example, receives key manifestfrom user deviceto determine whether user deviceis synchronized with user terminaland/or server(s)in terms of secure information stored in secure storageand secure information stored in secure storage. The secure information subject to backup and recovery can be fixed or variable based on configuration. For example, backup configurationcan indicate which information is backed up and conditions for backing up, such as following successful authentication and/or additional user credentials (which improve the reliability of the authentication, such as through multi-factor authentication). For example, recovery configurationcan indicate which information is recoverable and conditions for recovery, such as user credentials. User credentialsinclude one or more types of credentials, such as biometric, non-biometric, location, non-location, contactless, contact, and so on. For example, user credentials can include user location credential(s), such as three dimensional (3D) position, geo-location, and/or RADAR, and/or non-location credential(s), such as face recognition, voice recognition, gesture(s), movement pattern(s), key(s), and/or time and date.
148 106 102 148 148 148 148 142 142 142 148 144 140 106 142 144 148 148 104 120 102 106 f d f b a b b b f Security managerimplements user authentication, backup/synchronization, and recovery operations, such as configuration and implementation. An administrator of user terminal(e.g., user) uses one or more interfaces provided by security managerto specify user authentication procedures and associated user credentials, backup/synchronization configuration, recovery configuration, etc. Keys(and key manifestbased on keys) may be static or dynamic, e.g., generated by a key generator (not shown). Security managermay store user credentialsin secure storage. User terminalprovides keys, user credentials, backup configuration, and recovery configurationto user devicefor storage in secure storageand use in user authentication, secure information backup and recovery operations involving userand user terminal.
148 148 148 148 148 146 102 148 148 148 148 a c e a a b a b. Security managerincludes, for example, authentication manager, backup manager, and recovery manager. Authentication manageris configured to provide an interface for an administrator of user accessible environment(s)to configure a user authentication procedure and associated user credentials for user. Authentication manageris configured to generate authentication configuration. In an example, authentication manageris an authenticator that performs the authentication procedure based on authentication configuration
148 146 120 140 102 104 148 148 148 148 c c d c d. Backup manageris configured to provide an interface for an administrator of user accessible environment(s)to configure a backup/synchronization procedure for secure information stored in secure storagerelative to secure information stored in secure storagepertaining to userand user device. Backup manageris configured to generate backup configuration. Backup managercan be a synchronizer that performs the backup/synchronization procedure based on backup configuration
148 146 120 140 102 104 148 148 148 148 148 e e f f e f. Recovery manageris configured to provide an interface for an administrator of user accessible environment(s)to configure a recovery procedure using secure information stored in secure storageto recover secure information stored in secure storagepertaining to userand user device. Recovery manageris configured to generate recovery configuration. Recovery configurationincludes configuration information configured by the administrator (or other user) and indicates information that is recoverable and conditions for recovery of the information, providing all this information in a convenient package. In an example, recovery manageris a recoverer that performs the recovery procedure based on recovery configuration
148 150 110 102 162 148 104 104 110 164 168 170 166 Security manageris configured to communicate with security servicein server(s), which manages user authentication for userand other users to access user accessible environment(s). Security manageris configured to communicate with user device. User devicecan communicate with server(s)indirectly via local communicationsand network communications,, and/or directly via network communications.
108 104 106 110 108 Network(s)comprises one or more networks such as local area networks (LANs), wide area networks (WANs), Public Land Mobile Networks (PLMNs), enterprise networks, the Internet, etc., and may include one or more of wired and/or wireless portions. User device, user terminal, and/or server(s)may communicate with each other via network(s)to implement ML model creation, training, deployment, and/or user authorization.
110 150 102 152 162 110 150 102 152 162 110 162 Server(s)comprises one or more computing devices, servers, services, local processes, remote machines, web services, etc. configured for executing security service, storing secure information for userand other users in secure component, synchronizing the secure information, and providing access to user accessible environment(s). In an example, server(s)comprises a server located on an organization's premises and/or coupled to an organization's local network, a remotely located server, a cloud-based server (e.g., one or more servers in a distributed manner), or any other device or service that may host, manage, and/or provide resource(s) for execution of security service, storing secure information for userand other users in secure component, synchronizing the secure information, and/or providing access to user accessible environment(s). Server(s)may be implemented as a plurality of programs executed by one or more computing devices. In examples, user accessible environment(s)include computer network applications (e.g., word processing, job processing), real estate access card readers, financial/banking applications, etc.
150 110 150 148 106 110 150 148 160 158 158 158 150 160 156 110 158 160 106 104 140 120 102 106 b a b b Security serviceof server(s)implements user authentication, backup/synchronization, and recovery operations, such as configuration and implementation. Security servicemay be configured similarly to security managerin user terminal. An administrator of server(s)can use one or more interfaces provided by security serviceto (e.g., similar to security manager) specify user authentication procedures and associated user credentials, backup/synchronization configuration, recovery configuration, etc. Keys(and key manifestbased on keys) may be static or dynamic, e.g., generated by a key generator (not shown). Security servicecan store user credentialsin secure storage. Server(s)provides keys, user credentials, backup configuration, and recovery configuration to user terminaland/or devicefor storage, respectively, in secure storageand/or, and use in user authentication, secure information backup and recovery operations involving userand/or user terminal.
150 148 148 148 150 162 102 a Security servicecan include, for example, similar to security manager, an authentication manager, a backup manager, and a recovery manager. Similar to authentication managerin security manager, an authentication manager in security serviceis configured to provide an interface for an administrator of user accessible environment(s)to configure a user authentication procedure and associated user credentials for user. An authentication manager is configured to generate an authentication configuration. An authentication manager is an authenticator that performs the authentication procedure based on an authentication configuration.
148 148 150 162 120 156 102 104 c Similar to backup managerin security manager, a backup manager in security serviceis configured to provide an interface for an administrator for user accessible environment(s)to configure a backup/synchronization procedure for secure information stored in secure storagerelative to secure information stored in secure storagepertaining to userand user device. A backup manager is configured to generate a backup configuration. A backup manager is a synchronizer that performs the backup/synchronization procedure based on the backup configuration.
148 148 150 162 120 160 102 104 e Similar to recovery managerin security manager, a recovery manager in security serviceis configured to provide an interface for an administrator of user accessible environment(s)to configure a recovery procedure using secure information stored in secure storageto recover secure information stored in secure storagepertaining to userand user device. A recovery manager is configured to generate a recovery configuration. A recovery manager is a recoverer that performs the recovery procedure based on the recovery configuration.
150 148 106 150 148 102 146 162 148 104 104 110 164 168 170 166 Security serviceis configured to communicate with security managerin user terminal. Security serviceand/or security managercan manage user authentication for userand other users to access user accessible environment(s)and/or. Security manageris configured to communicate with user device. User devicecan communicate with server(s)indirectly via local communicationsand network communications,, and/or directly via network communications.
152 152 110 152 152 154 156 152 154 Secure componentrepresents a secure platform module, such as a trusted platform module (TPM). Secure componentprovides an isolated secure environment not affected by other software (e.g., malware) that may exist on server(s)outside of secure component. Secure componentincludes secure processorand secure storage. Secure componentincludes a secure operating system (OS) (not shown) executed by secure processor.
156 158 160 158 158 158 158 158 158 104 122 172 106 164 110 108 166 158 156 120 a b a b b b b Secure storageincludes any data an administrator/user seeks to protect, such as key database, user credentials, etc. Key databaseincludes key manifestand keys. Key manifestindicates each key among keys. Keysmay be provided to user deviceas keysto use to generate secure tokento be transmitted to user terminalin communicationand/or to server(s)via network(s)in communication. Keysinclude, for example, public keys, private keys, cloud keys, and/or secure shell (SSH) keys. The contents of secure storagemay be synchronized to and recovered from secure storage.
154 156 160 158 158 154 156 b a Secure processoris a tamper-resistant processor that protects secure assets stored in secure storage, such as a root of trust, sensitive data, such as user credentials, keys, key manifest, certificates, disc encryption recovery key, applications, etc. against attacks attempting to use software or hardware. Secure processorprocesses executable code (e.g., programs or applications) to perform operations that access, modify, send, receive, and store data in secure storage.
154 148 148 104 106 126 128 156 120 120 154 122 104 104 106 110 120 140 156 148 148 160 d f a d f Secure processoris configured to execute operations to provide a backup configuration (e.g., backup configuration) and a recovery configuration (e.g., recovery configuration) to user device, directly or indirectly via user terminal, to store as backup configurationand recovery configuration, respectively, to backup/synchronize secure information stored in secure storagewith secure information stored in secure storage, and to recover secure information stored in secure storage. Secure processor, for example, receives key manifestfrom user deviceto determine whether user deviceis synchronized with user terminaland/or server(s)in terms of secure information stored in secure storageand secure information stored in secure storageand/or secure storage. The secure information subject to backup and recovery is fixed or variable based on configuration. For example, a backup configuration (e.g., backup configuration) can indicate which information is backed up and conditions for backing up, such as following successful authentication and/or additional user credentials. For example, a recovery configuration (e.g., recovery configuration) can indicate which information is recoverable and conditions for recovery, such as user credentials. User credentialsinclude one or more types of credentials, such as biometric, non-biometric, location, non-location, contactless, contact, and so on. For example, user credentials can include user location credential(s), such as three dimensional (3D) position, geo-location, and/or RADAR, and/or non-location credential(s), such as face recognition, voice recognition, gesture(s), movement pattern(s), key(s), and/or time and date.
110 102 102 104 106 110 104 106 102 148 106 102 104 106 10 148 150 102 104 106 148 150 102 126 148 150 In an example, server(s)may authenticate userto determine authorization for userto use user deviceto check a bank balance provided by user terminalor server(s). In an embodiment, user deviceand user terminalinclude at least one UWB-enabled device. There may be additional people in the room area with user. Security managercan verify which person is which (e.g., center, right, left) and distance from user terminalto determine whether the interaction with userand/or user deviceproviding credentials is secure. For example, user terminalmay receive biometric information/user credentials for user. Security manageror security servicecan determine a proximity of user, for example, based on UWB communication(s) between user deviceand user terminal. Security managerand/or security servicecan determine whether useris authenticated based on inferences provided by one or more trained modelsbased on the biometric and proximity information/user credentials provided for authentication/authorization. Other examples can be configured using other user credential information for processing by security managerand/or security service.
104 106 110 104 106 110 200 200 1 FIG. 2 FIG. 2 FIG. 2 FIG. For illustrative purposes, further example operation of user device, user terminal, and server(s), shown in, is described below with respect to.shows an interaction diagram for an example system configured for non-contact authentication for key recovery and platform security provisioning, in accordance with an embodiment. User device, user terminal, and server(s)may be configured to operate according to interaction diagramin embodiments. Note that not all steps of interaction diagramneed be performed in all embodiments. Further structural and operational embodiments will be apparent to persons skilled in the relevant art(s) based on the following description of.
200 202 204 206 208 202 210 214 204 216 224 206 226 246 208 248 264 Interaction diagramshows four phases of interaction, including configuration, authentication, backup/synchronization, and recovery. Configurationincludes interaction operations-. Authenticationincludes interaction operations-. Backup/synchronizationincludes interaction operations-. Recoveryincludes interaction operations-.
202 210 214 210 110 110 106 104 Configurationincludes interaction operations-. In operation, serverconfigures backup and recovery operations, for example, based on an admin using a user interface. Servermay be configured to provide the configuration(s) to user terminaland/or to user device.
212 106 110 104 In operation, user terminal configures backup and recovery operations, for example, based on an admin using a user interface. User terminalmay be configured to provide the configuration(s) to server(s)and/or to user device
214 104 106 110 104 110 104 106 212 110 214 In operation, user deviceis configured by receiving backup and recovery configuration(s) from user terminaland/or server. User devicemay receive the configuration(s) directly or indirectly from server. The configuration(s) received by user devicemay be configured and/or provided by user terminalin operationand/or by serverin operation.
204 216 224 216 104 106 110 172 106 110 Authenticationincludes interaction operations-. In operation, user device(e.g., coupled to user terminaland/or server(s)) sends secure token, alone or with other user credentials, during an authentication procedure by user terminaland/or server(s).
218 206 In operation, user terminaldetects the token (e.g., and credentials) and initiates authentication.
220 206 104 In operation, user terminalsends a challenge response to the token to the secure component in user device.
222 104 106 106 In operation, user device(e.g., and secure component) receives and determines whether the challenge response from the user (host) terminalis valid, providing a confirmation to user terminalif valid.
224 106 102 104 In operation, user terminalauthenticates the received token (e.g., and credentials) based on a comparison to known authentication information for userand/or user device.
106 110 Successful authentication may be a condition (e.g., among multiple conditions, such as expiration of a time period) used by user terminaland/or server(s)to initiate backup/synchronization.
206 226 246 226 104 106 104 110 Backup/synchronizationincludes interaction operations-. In operation, user deviceuser terminaltransmits a backup request to user devicebased on the backup configuration. The request could also be generated by server(s).
228 104 106 110 In operation, user devicereceives and processes the backup service sync request from user terminaland/or server(s).
230 104 122 120 In operation, user deviceunlocks its key database(e.g., or secure storagegenerally) to service the backup request.
232 104 122 120 106 a In operation, user deviceprovides key manifest(e.g., and/or other secure information in secure storage) to user (host) terminal.
234 106 122 120 104 142 a a. In operation, user terminaldetermines if the key manifest(e.g., and/or other secure information in secure storage) provided by user deviceis synchronized with key manifest
236 106 122 120 110 a In operation, user terminalprovides key manifest(e.g., and/or other secure information in secure storage) to server(s).
238 110 122 120 158 a a. In operation, server(s)receives key manifest(e.g., and/or other secure information in secure storage) and determines whether it is synchronized with key manifest
240 110 120 106 104 122 120 b In operation, server(s)provides any missing keys (e.g., and/or other secure information in secure storage) to user terminaland/or user deviceto synchronize keys(e.g., and/or other secure information in secure storage).
242 106 120 106 104 122 120 b In operation, user terminalprovides any missing keys (e.g., and/or other secure information in secure storage) to user terminaland/or user deviceto synchronize keys(e.g., and/or other secure information in secure storage).
244 104 120 106 110 122 120 b In operation, user devicereceives any missing keys (e.g., and/or other secure information in secure storage) from user terminaland/or server(s)to synchronize keys(e.g., and/or other secure information in secure storage).
246 120 140 156 120 120 106 110 In operation, user device synchronizes secure storagewith secure storageand/or secure storageby storing in secure storagereceived missing keys (e.g., and/or other secure information in secure storage) received from user terminaland/or server(s).
208 248 264 248 106 Recoveryincludes interaction operations-. In operation, user terminalgenerates a user credential (e.g., and/or other secure information) fault.
250 110 In operation, server(s)generates a user credential (e.g., and/or other secure information) fault.
252 110 120 104 104 106 In operation, server(s)generate (e.g., and send) a user credential (e.g., and/or other secure information in secure storage) recovery request, which may proceed directly to user deviceor indirectly to user devicethrough user terminal.
254 106 120 110 In operation, user terminalgenerates a user credential (e.g., and/or other secure information in secure storage) recovery request based on the fault it generated and/or based on the fault received from server(s).
256 206 104 In step, user terminalsends the user credential recovery request to user device.
258 104 120 In operation, user devicereceives the user credential (e.g., and/or other secure information in secure storage) recovery request.
260 124 120 106 110 In operation, user device provides user credentials(e.g., and/or other secure information in secure storage) to user terminal(e.g., or directly to server(s)).
262 106 124 120 104 In operation, user terminalreceives the user credentials(e.g., and/or other secure information in secure storage) recovered from user device.
264 110 124 120 104 In operation, server(s)receive the user credentials(e.g., and/or other secure information in secure storage) recovered from user device.
104 106 110 300 104 106 110 300 300 1 FIG. 3 FIG. 3 FIG. 3 FIG. For illustrative purposes, further example operation of user device, user terminal, and server(s), shown in, is described below with respect to.shows a flowchartof a process for implementing non-contact authentication for key recovery and platform security provisioning in a user device, in accordance with an embodiment. User device, user terminal, and server(s)may be configured to operate according to flowchartin embodiments. Note that not all steps of flowchartneed be performed in all embodiments. Further structural and operational embodiments will be apparent to persons skilled in the relevant art(s) based on the following description of.
300 104 302 118 172 122 124 1 FIG. b Flowchartshows an example of operations from the perspective of user device. In operation, a secure token may be retrieved from (e.g., or generated based on) secure information in secure storage in the secure component. For example, as shown in, secure processorexecutes instructions to generate secure tokenbased on one or more keysand at least one user credential(e.g., password).
304 118 114 172 106 204 1 FIG. In operation, the secure token is wirelessly provided to a host device performing authentication of a user. For example, as shown in, secure processoruses transceiver(s)to wirelessly transmit the secure tokento user terminalduring authentication.
306 114 106 106 102 1 FIG. In operation, in response to the user being authenticated by the host device, a user credential synchronization request is received from the host device. For example, as shown in, transceiver(s)receives a user credential synchronization request from user terminalif host deviceauthenticated user.
308 118 122 114 122 106 1 FIG. a a In operation, a key manifest is provided to the host device in response to the user credential synchronization request. For example, as shown in, in response to receiving a request for synchronization, secure processoraccesses key manifestand uses transceiver(s)to wirelessly transmit key manifestto user terminal.
310 104 106 110 106 110 122 142 158 1 FIG. a a a. In operation, in response to a determination the key manifest is unsynchronized based on the absence of one or more user credentials, the one or more absent user credentials are received. For example, as shown in, user devicewill receive one or more keys from user terminaland/or server(s)if user terminaland/or server(s)determine that key manifestis missing any keys present in key manifestand/or key manifest
312 118 122 122 1 FIG. b a In operation, the received one or more absent user credentials are stored in the secure storage to synchronize the user credentials with at least one external user credential store. For example, as shown in, in response to receiving one or more missing keys, secure processorstores the received keys with keysand updates key manifestto complete the synchronization operation.
104 106 110 4 400 104 106 110 400 400 1 FIG. 4 FIG. 4 FIG. For illustrative purposes, further example operation of user device, user terminal, and server(s), shown in, is described below with respect to FIG..shows a flowchartof a process for implementing non-contact authentication for key recovery and platform security provisioning in a host device, in accordance with embodiments. User device, user terminal, and server(s)may be configured to operate according to flowchartin embodiments. Note that not all steps of flowchartneed be performed in all embodiments. Further structural and operational embodiments will be apparent to persons skilled in the relevant art(s) based on the following description of.
400 106 402 106 172 104 204 1 FIG. Flowchartshows an example of operations from the perspective of user terminal. In operation, a secure token is wirelessly received from secure storage in an external secure component. For example, as shown in, user terminalreceives secure tokentransmitted by user deviceduring authentication.
404 148 106 102 172 1 FIG. In operation, authentication of a user is performed based on the secure token. For example, as shown in, security managerin user terminalperforms user authentication for userbased on the received secure token.
406 148 102 148 148 134 104 206 1 FIG. c In operation, in response to the user being authenticated, a user credential synchronization request is transmitted to the secure component. For example, as shown in, if security managerauthenticates user, security manager(e.g., backup manager) will, based on the authentication, cause transceiver(s)to transmit a user credential synchronization request to user deviceduring a backup operation.
408 106 122 114 104 1 FIG. a In operation, a key manifest is received from the secure component in response to the user credential synchronization request. For example, as shown in, user terminalreceives key manifestin a transmission from transceiver(s)in user device.
410 148 148 122 142 104 148 134 104 122 104 1 FIG. c a a c b In operation, in response a determination the key manifest is unsynchronized based on the absence of one or more user credentials, transmit the one or more absent user credentials to the secure component for storage in the secure storage to synchronize the user credentials in the secure component with a user credential store. For example, as shown in, backup managerin security managerwill compare received key manifestto key manifestto determine whether user deviceis synchronized. If user device is determined to be unsynchronized, backup managerwill cause transceiver(s)to transmit any missing keys to user deviceto store with keysto complete synchronization of user device.
104 106 110 500 104 106 110 500 500 1 FIG. 5 FIG. 5 FIG. 5 FIG. For illustrative purposes, further example operation of user device, user terminal, and server(s), shown in, is described below with respect to.shows a flowchartof a process for implementing non-contact authentication for key recovery and platform security provisioning in a server, in accordance with an embodiment. User device, user terminal, and server(s)may be configured to operate according to flowchartin embodiments. Note that not all steps of flowchartneed be performed in all embodiments. Further structural and operational embodiments will be apparent to persons skilled in the relevant art(s) based on the following description of.
500 110 502 102 106 104 122 116 106 110 122 106 1 FIG. a a Flowchartshows an example of operations from the perspective of user server(s). In operation, a user credential synchronization request comprising a key manifest for a secure component is received from a host device in response to a user credential synchronization request provided by the host device to the secure component following authentication of a secure token received by the host device from the secure component. For example, as shown in, following authentication of user, user terminalsends a synchronization request to user device, which responds by providing key manifestfrom secure componentto user terminal. Server(s)receive key manifestfrom user terminal.
504 150 122 158 152 104 1 FIG. a a In operation, a determination is made whether the key manifest provided by the secure component is synchronized with user credentials in a user credential store managed by the server. For example, as shown in, security servicewill compare received key manifestto key manifestin secure componentto determine whether user deviceis synchronized.
506 150 104 150 110 104 106 108 104 122 104 1 FIG. b In operation, if the key manifest is determined to be unsynchronized based on the absence of one or more user credentials, the one or more absent user credentials are transmitted to the host device for transmission to the secure component to synchronize the user credentials in the secure component with the user credential store managed by the server. For example, as shown in, if security servicedetermines that user deviceis unsynchronized, security servicewill cause transceiver(s) in server(s)to transmit any missing keys to user devicevia user terminalthrough network(s)for deviceto store with keysto complete synchronization of user device.
104 106 110 116 118 120 122 122 122 124 126 128 136 138 140 142 142 142 144 148 148 148 148 148 148 148 150 152 154 156 158 158 158 160 200 300 400 500 104 106 110 116 118 120 122 122 122 124 126 128 136 138 140 142 142 142 144 148 148 148 148 148 148 148 150 152 154 156 158 158 158 160 200 300 400 500 104 106 110 116 118 120 122 122 122 124 126 128 136 138 140 142 142 142 144 148 148 148 148 148 148 148 150 152 154 156 158 158 158 160 200 300 400 500 a b a b a b c d e f a b a b a b a b c d e f a b a b a b a b c d e f a b User device, user terminal, server(s), secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, backup configuration, recovery configuration, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, security manager, authentication manager, authentication configuration, backup manager, backup configuration, recovery manager, recovery configuration, security service, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, interaction diagram, flowchart, flowchart, and flowchart, are implemented in hardware, or hardware combined with one or both of software and/or firmware. For example, user device, user terminal, server(s), secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, backup configuration, recovery configuration, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, security manager, authentication manager, authentication configuration, backup manager, backup configuration, recovery manager, recovery configuration, security service, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, interaction diagram, flowchart, flowchart, and flowchartare each implemented as computer program code/instructions configured to be executed in one or more processors and stored in a computer readable storage medium. Alternatively, user device, user terminal, server(s), secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, backup configuration, recovery configuration, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, security manager, authentication manager, authentication configuration, backup manager, backup configuration, recovery manager, recovery configuration, security service, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, interaction diagram, flowchart, flowchart, and flowchartare implemented in one or more SoCs (system on chip). An SoC includes an integrated circuit chip that includes one or more of a processor (e.g., a central processing unit (CPU), microcontroller, microprocessor, digital signal processor (DSP), etc.), memory, one or more communication interfaces, and/or further circuits, and optionally executes received program code and/or include embedded firmware to perform functions.
6 FIG. 6 FIG. 6 FIG. 600 602 602 104 106 110 602 602 600 604 604 604 604 602 Embodiments disclosed herein can be implemented in one or more computing devices that are mobile (a mobile device) and/or stationary (a stationary device) and include any combination of the features of such mobile and stationary computing devices. Examples of computing devices in which embodiments are implementable are described as follows with respect to.shows a block diagram of an exemplary computing environmentthat includes a computing device. Computing deviceis an example of each of user device, user terminaland server, which may each include one or more of the components of computing device. In some embodiments, computing deviceis communicatively coupled with devices (not shown in) external to computing environmentvia network. Networkcomprises one or more networks such as local area networks (LANs), wide area networks (WANs), enterprise networks, the Internet, etc. In examples, networkincludes one or more wired and/or wireless portions. In some examples, networkadditionally or alternatively includes a cellular network for cellular communications. Computing deviceis described in detail as follows.
602 602 602 Computing deviceis any of a variety of types of computing devices. Examples of computing deviceinclude a mobile computing device such as a handheld computer (e.g., a personal digital assistant (PDA)), a laptop computer, a tablet computer, a hybrid device, a notebook computer, a netbook, a mobile phone (e.g., a cell phone, a smart phone, etc.), a wearable computing device (e.g., a head-mounted augmented reality and/or virtual reality device including smart glasses), or other type of mobile computing device. In an alternative example, computing deviceis a stationary computing device such as a desktop computer, a personal computer (PC), a stationary server device, a minicomputer, a mainframe, a supercomputer, etc.
6 FIG. 6 FIG. 602 610 620 642 644 630 650 660 680 682 684 686 620 656 622 624 688 620 612 614 616 660 662 664 666 650 652 654 630 632 634 636 638 640 602 602 602 602 602 602 As shown in, computing deviceincludes a variety of hardware and software components, including a processor, a storage, a graphics processing unit (GPU), a neural processing unit (NPU), one or more input devices, one or more output devices, one or more wireless modems, one or more wired interfaces, a power supply, a location information (LI) receiver, and an accelerometer. Storageincludes memory, which includes non-removable memoryand removable memory, and a storage device. Storagealso stores an operating system, application programs, and application data. Wireless modem(s)include a Wi-Fi modem, a Bluetooth modem, and a cellular modem. Output device(s)includes a speakerand a display. Input device(s)includes a touch screen, a microphone, a camera, a physical keyboard, and a trackball. Not all components of computing deviceshown inare present in all embodiments, additional components not shown may be present, and in a particular embodiment any combination of the components are present. In examples, components of computing deviceare mounted to a circuit card (e.g., a motherboard) of computing device, integrated in a housing of computing device, or otherwise included in computing device. The components of computing deviceare described as follows.
610 610 602 610 610 612 614 620 610 612 602 614 614 610 644 642 In embodiments, a single processor(e.g., central processing unit (CPU), microcontroller, a microprocessor, signal processor, ASIC (application specific integrated circuit), and/or other physical hardware processor circuit) or multiple processorsare present in computing devicefor performing such tasks as program execution, signal coding, data processing, input/output processing, power control, and/or other functions. In examples, processoris a single-core or multi-core processor, and each processor core is single-threaded or multithreaded (to provide multiple threads of execution concurrently). Processoris configured to execute program code stored in a computer readable medium, such as program code of operating systemand application programsstored in storage. The program code is structured to cause processorto perform operations, including the processes/methods disclosed herein. Operating systemcontrols the allocation and usage of the components of computing deviceand provides support for one or more application programs(also referred to as “applications” or “apps”). In examples, application programsinclude common computing applications (e.g., e-mail applications, calendars, contact managers, web browsers, messaging applications), further computing applications (e.g., word processing applications, mapping applications, media player applications, productivity suite applications), one or more machine learning (ML) models, as well as applications related to the embodiments disclosed elsewhere herein. In examples, processor(s)includes one or more general processors (e.g., CPUs) configured with or coupled to one or more hardware accelerators, such as one or more NPUsand/or one or more GPUs.
602 606 610 602 606 6 FIG. Any component in computing devicecan communicate with any other component according to function, although not all connections are shown for ease of illustration. For instance, as shown in, busis a multiple signal line communication medium (e.g., conductive traces in silicon, metal traces along a motherboard, wires, etc.) present to communicatively couple processorto various other components of computing device, although in other embodiments, an alternative bus, further buses, and/or one or more individual signal lines is/are present to communicatively couple components. Busrepresents one or more of any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures.
620 656 688 612 614 616 622 622 610 622 618 618 624 602 602 624 688 602 688 6 FIG. Storageis physical storage that includes one or both of memoryand storage device, which store operating system, application programs, and application dataaccording to any distribution. Non-removable memoryincludes one or more of RAM (random access memory), ROM (read only memory), flash memory, a solid-state drive (SSD), a hard disk drive (e.g., a disk drive for reading from and writing to a hard disk), and/or other physical memory device type. In examples, non-removable memoryincludes main memory and is separate from or fabricated in a same integrated circuit as processor. As shown in, non-removable memorystores firmwarethat is present to provide low-level control of hardware. Examples of firmwareinclude BIOS (Basic Input/Output System, such as on personal computers) and boot firmware (e.g., on smart phones). In examples, removable memoryis inserted into a receptacle of or is otherwise coupled to computing deviceand can be removed by a user from computing device. Removable memorycan include any suitable removable memory device type, including an SD (Secure Digital) card, a Subscriber Identity Module (SIM) card, which is well known in GSM (Global System for Mobile Communications) communication systems, and/or other removable physical memory device type. In examples, one or more of storage deviceare present that are internal and/or external to a housing of computing deviceand are or are not removable. Examples of storage deviceinclude a hard disk drive, a SSD, a thumb drive (e.g., a USB (Universal Serial Bus) flash drive), or other physical storage device.
620 612 614 104 106 110 116 118 120 122 122 122 124 126 128 136 138 140 142 142 142 144 148 148 148 148 148 148 148 150 152 154 156 158 158 158 160 200 300 400 500 a b a b a b c d e f a b One or more programs are stored in storage. Such programs include operating system, one or more application programs, and other program modules and program data. Examples of such application programs include computer program logic (e.g., computer program code/instructions) for implementing user device, user terminal, server(s), secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, backup configuration, recovery configuration, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, security manager, authentication manager, authentication configuration, backup manager, backup configuration, recovery manager, recovery configuration, security service, secure component, secure processor, secure storage, key database, key manifest, keys, user credentials, interaction diagram, flowchart, flowchart, and flowchart, and/or any individual steps thereof.
620 612 614 616 616 616 620 Storagealso stores data used and/or generated by operating systemand application programsas application data. Examples of application datainclude web pages, text, images, tables, sound files, video data, and other data. In examples, application datais sent to and/or received from one or more network servers or other devices via one or more wired or wireless networks. Storageis used to store further data including a subscriber identifier, such as an International Mobile Subscriber Identity (IMSI), and an equipment identifier, such as an International Mobile Equipment Identifier (IMEI). Such identifiers can be transmitted to a network server to identify users and equipment.
602 630 602 650 630 632 634 636 638 640 650 652 654 630 650 602 602 602 602 680 660 630 654 632 630 650 634 636 652 654 In examples, a user enters commands and information into computing devicethrough one or more input devicesand receives information from computing devicethrough one or more output devices. Input device(s)includes one or more of touch screen, microphone, camera, physical keyboardand/or trackballand output device(s)includes one or more of speakerand display. Each of input device(s)and output device(s)are integral to computing device(e.g., built into a housing of computing device) or are external to computing device(e.g., communicatively coupled wired or wirelessly to computing devicevia wired interface(s)and/or wireless modem(s)). Further input devices(not shown) can include a Natural User Interface (NUI), a pointing device (computer mouse), a joystick, a video game controller, a scanner, a touch pad, a stylus pen, a voice recognition system to receive voice input, a gesture recognition system to receive gesture input, or the like. Other possible output devices (not shown) can include piezoelectric or other haptic output devices. Some devices can serve more than one input/output function. For instance, displaydisplays information, as well as operating as touch screenby receiving user commands and/or other information (e.g., by touch, finger gestures, virtual keyboard, etc.) as a user interface. Any number of each type of input device(s)and output device(s)are present, including multiple microphones, multiple cameras, multiple speakers, and/or multiple displays.
642 642 642 In embodiments where GPUis present, GPUincludes hardware (e.g., one or more integrated circuit chips that implement one or more of processing cores, multiprocessors, compute units, etc.) configured to accelerate computer graphics (two-dimensional (2D) and/or three-dimensional (3D)), perform image processing, and/or execute further parallel processing applications (e.g., training of neural networks, etc.). Examples of GPUperform calculations related to 3D computer graphics, include 2D acceleration and framebuffer capabilities, accelerate memory-intensive work of texture mapping and rendering polygons, accelerate geometric calculations such as the rotation and translation of vertices into different coordinate systems, support programmable shaders that manipulate vertices and textures, perform oversampling and interpolation techniques to reduce aliasing, and/or support very high-precision color spaces.
644 628 644 644 In examples, NPU(also referred to as an “artificial intelligence (AI) accelerator” or “deep learning processor (DLP)”) is a processor or processing unit configured to accelerate artificial intelligence and machine learning applications, such as execution of machine learning (ML) model (MLM). In an example, NPUis configured for a data-driven parallel computing and is highly efficient at processing massive multimedia data such as videos and images and processing data for neural networks. NPUis configured for efficient handling of AI-related tasks, such as speech recognition, background blurring in video calls, photo or video editing processes like object detection, etc.
644 628 628 In embodiments disclosed herein that implement ML models, NPUcan be utilized to execute such ML models, of which MLMis an example. For instance, where applicable, MLMis a generative AI model that generates content that is complex, coherent, and/or original. For instance, a generative AI model can create sophisticated sentences, lists, ranges, tables of data, images, essays, and/or the like. An example of a generative AI model is a language model. A language model is a model that estimates the probability of a token or sequence of tokens occurring in a longer sequence of tokens. In this context, a “token” is an atomic unit that the model is training on and making predictions on. Examples of a token include, but are not limited to, a word, a character (e.g., an alphanumeric character, a blank space, a symbol, etc.), a sub-word (e.g., a root word, a prefix, or a suffix). In other types of models (e.g., image based models) a token may represent another kind of atomic unit (e.g., a subset of an image). Examples of language models applicable to embodiments herein include large language models (LLMs), text-to-image AI image generation systems, text-to-video AI generation systems, etc. A large language model (LLM) is a language model that has a high number of model parameters. In examples, an LLM has millions, billions, trillions, or even greater numbers of model parameters. Model parameters of an LLM are the weights and biases the model learns during training. Some implementations of LLMs are transformer-based LLMs (e.g., the family of generative pre-trained transformer (GPT) models). A transformer is a neural network architecture that relies on self-attention mechanisms to transform a sequence of input embeddings into a sequence of output embeddings (e.g., without relying on convolutions or recurrent neural networks).
644 628 628 628 628 628 628 628 628 628 644 628 In further examples, NPUis used to train MLM. To train MLM, training data is that includes input features (attributes) and their corresponding output labels/target values (e.g., for supervised learning) is collected. A training algorithm is a computational procedure that is used so that MLMlearns from the training data. Examples of training inputs for ML model training include user position, angle, gesture, time of day, location, user crypto, etc. Parameters/weights are internal settings of MLMthat are adjusted during training by the training algorithm to reduce a difference between predictions by MLMand actual outcomes (e.g., output labels). In some examples, MLMis set with initial values for the parameters/weights. A loss function measures a dissimilarity between predictions by MLMand the target values, and the parameters/weights of MLMare adjusted to minimize the loss function. The parameters/weights are iteratively adjusted by an optimization technique, such as gradient descent. In this manner, MLMis generated through training by NPUto be used to generate inferences based on received input feature sets for particular applications. MLMis generated as a computer program or other type of algorithm configured to generate an output (e.g., a classification, a prediction/inference) based on received input features and is stored in the form of a file or other data structure.
628 644 628 644 628 In examples, such training of MLMby NPUis supervised or unsupervised. According to supervised learning, input objects (e.g., a vector of predictor variables) and a desired output value (e.g., a human-labeled supervisory signal) train MLM. The training data is processed, building a function that maps new data on expected output values. Example algorithms usable by NPUto perform supervised training of MLMin particular implementations include support-vector machines, linear regression, logistic regression, Naïve Bayes, linear discriminant analysis, decision trees, K-nearest neighbor algorithm, neural networks, and similarity learning.
628 628 In an example of supervised learning where MLMis an LLM, MLMcan be trained by exposing the LLM to (e.g., large amounts of) text (e.g., predetermined datasets, books, articles, text-based conversations, webpages, transcriptions, forum entries, and/or any other form of text and/or combinations thereof). In examples, training data is provided from a database, from the Internet, from a system, and/or the like. Furthermore, an LLM can be fine-tuned using Reinforcement Learning with Human Feedback (RLHF), where the LLM is provided the same input twice and provides two different outputs and a user ranks which output is preferred. In this context, the user's ranking is utilized to improve the model. Further still, in example embodiments, an LLM is trained to perform in various styles, e.g., as a completion model (a model that is provided a few words or tokens and generates words or tokens to follow the input), as a conversation model (a model that provides an answer or other type of response to a conversation-style prompt), as a combination of a completion and conversation model, or as another type of LLM model.
628 628 628 628 628 644 628 According to unsupervised learning, MLMis trained to learn patterns from unlabeled data. For instance, in embodiments where MLMimplements unsupervised learning techniques, MLMidentifies one or more classifications or clusters to which an input belongs. During a training phase of MLMaccording to unsupervised learning, MLMtries to mimic the provided training data and uses the error in its mimicked output to correct itself (i.e., correct weights and biases). In further examples, NPUperform unsupervised training of MLMaccording to one or more alternative techniques, such as Hopfield learning rule, Boltzmann learning rule, Contrastive Divergence, Wake Sleep, Variational Inference, Maximum Likelihood, Maximum A Posteriori, Gibbs Sampling, and backpropagating reconstruction errors or hidden state reparameterizations.
644 610 642 644 628 Note that NPUneed not necessarily be present in all ML model embodiments. In embodiments where ML models are present, any one or more of processor, GPU, and/or NPUcan be present to train and/or execute MLM.
660 602 610 602 604 660 666 660 664 662 662 664 One or more wireless modemscan be coupled to antenna(s) (not shown) of computing deviceand can support two-way communications between processorand devices external to computing devicethrough network, as would be understood to persons skilled in the relevant art(s). Wireless modemis shown generically and can include a cellular modemfor communicating with one or more cellular networks, such as a GSM network for data and voice communications within a single cellular network, between cellular networks, or between the mobile device and a public switched telephone network (PSTN). In examples, wireless modemalso or alternatively includes other radio-based modem types, such as a Bluetooth modem(also referred to as a “Bluetooth device”) and/or Wi-Fi modem(also referred to as an “wireless adaptor”). Wi-Fi modemis configured to communicate with an access point or other remote Wi-Fi-capable device according to one or more of the wireless network protocols based on the IEEE (Institute of Electrical and Electronics Engineers) 802.11 family of standards, commonly used for local area networking of devices and Internet access. Bluetooth modemis configured to communicate with another Bluetooth-capable device according to the Bluetooth short-range wireless technology standard(s) such as IEEE 802.15.1 and/or managed by the Bluetooth Special Interest Group (SIG).
602 682 684 686 680 680 680 602 602 604 602 602 654 652 636 638 682 602 602 602 684 602 602 686 602 Computing devicecan further include power supply, LI receiver, accelerometer, and/or one or more wired interfaces. Example wired interfacesinclude a USB port, IEEE 1394 (FireWire) port, a RS-232 port, an HDMI (High-Definition Multimedia Interface) port (e.g., for connection to an external display), a DisplayPort port (e.g., for connection to an external display), an audio port, and/or an Ethernet port, the purposes and functions of each of which are well known to persons skilled in the relevant art(s). Wired interface(s)of computing deviceprovide for wired connections between computing deviceand network, or between computing deviceand one or more devices/peripherals when such devices/peripherals are external to computing device(e.g., a pointing device, display, speaker, camera, physical keyboard, etc.). Power supplyis configured to supply power to each of the components of computing deviceand receives power from a battery internal to computing device, and/or from a power cord plugged into a power port of computing device(e.g., a USB port, an A/C power port). LI receiveris useable for location determination of computing deviceand in examples includes a satellite navigation receiver such as a Global Positioning System (GPS) receiver and/or includes other type of location determiner configured to determine location of computing devicebased on received information (e.g., using cell tower triangulation, etc.). Accelerometer, when present, is configured to determine an orientation of computing device.
602 602 610 656 602 Note that the illustrated components of computing deviceare not required or all-inclusive, and fewer or greater numbers of components can be present as would be recognized by one skilled in the art. In examples, computing deviceincludes one or more of a gyroscope, barometer, proximity sensor, ambient light sensor, digital compass, etc. In an example, processorand memoryare co-located in a same semiconductor device package, such as being included together in an integrated circuit chip, FPGA, or system-on-chip (SOC), optionally along with further components of computing device.
602 620 610 In embodiments, computing deviceis configured to implement any of the above-described features of flowcharts herein. Computer program logic for performing any of the operations, steps, and/or functions described herein is stored in storageand executed by processor.
670 600 602 604 670 670 672 672 672 674 674 604 674 604 674 6 FIG. 6 FIG. In some embodiments, server infrastructureis present in computing environmentand is communicatively coupled with computing devicevia network. Server infrastructure, when present, is a network-accessible server set (e.g., a cloud-based environment or platform). As shown in, server infrastructureincludes clusters. Each of clusterscomprises a group of one or more compute nodes and/or a group of one or more storage nodes. For example, as shown in, clusterincludes nodes. Each of nodesare accessible via network(e.g., in a “cloud-based” embodiment) to build, deploy, and manage applications and services. In examples, any of nodesis a storage node that comprises a plurality of physical storage disks, SSDs, and/or other physical storage devices that are accessible via networkand are configured to store data associated with the applications and services managed by nodes.
674 674 602 674 674 646 648 658 610 642 644 602 648 676 678 658 676 678 646 674 676 6 FIG. Each of nodes, as a compute node, comprises one or more server computers, server systems, and/or computing devices. For instance, a nodein accordance with an embodiment includes one or more of the components of computing devicedisclosed herein. Each of nodesis configured to execute one or more software applications (or “applications”) and/or services and/or manage hardware resources (e.g., processors, memory, etc.), which are utilized by users (e.g., customers) of the network-accessible server set. In examples, as shown in, nodesincludes a nodethat includes storageand/or one or more of a processor(e.g., similar to processor, GPU, and/or NPUof computing device). Storagestores application programsand application data. Processor(s)operate application programswhich access and/or generate related application data. In an implementation, nodes such as nodeof nodesoperate or comprise one or more virtual machines, with each virtual machine emulating a system architecture (e.g., an operating system), in an isolated manner, upon which applications such as application programsare executed.
672 672 600 In embodiments, one or more of clustersare located/co-located (e.g., housed in one or more nearby buildings with associated components such as backup power supplies, redundant data communications, environmental controls, etc.) to form a datacenter, or are arranged in other manners. Accordingly, in an embodiment, one or more of clustersare included in a datacenter in a distributed collection of datacenters. In embodiments, exemplary computing environmentcomprises part of a cloud-based platform.
602 676 602 In an embodiment, computing deviceaccesses application programsfor execution in any manner, such as by a client application and/or a browser at computing device.
602 614 616 670 676 678 612 614 620 670 In an example, for purposes of network (e.g., cloud) backup and data security, computing deviceadditionally and/or alternatively synchronizes copies of application programsand/or application datato be stored at network-based server infrastructureas application programsand/or application data. In examples, operating systemand/or application programsinclude a file hosting service client configured to synchronize applications and/or data stored in storageat network-based server infrastructure.
692 600 602 604 692 692 698 692 602 692 696 602 692 694 696 698 690 610 642 644 602 696 690 696 602 614 616 692 696 698 In some embodiments, on-premises serversare present in computing environmentand are communicatively coupled with computing devicevia network. On-premises servers, when present, are hosted within an organization's infrastructure and, in many cases, physically onsite of a facility of that organization. On-premises serversare controlled, administered, and maintained by IT (Information Technology) personnel of the organization or an IT partner to the organization. Application datacan be shared by on-premises serversbetween computing devices of the organization, including computing device(when part of an organization) through a local network of the organization, and/or through further networks accessible to the organization (including the Internet). Furthermore, in examples, on-premises serversserve applications such as application programsto the computing devices of the organization, including computing device. Accordingly, in examples, on-premises serversinclude storage(which includes one or more physical storage devices such as storage disks and/or SSDs) for storage of application programsand application dataand include a processor(e.g., similar to processor, GPU, and/or NPUof computing device) for execution of application programs. In some embodiments, multiple processorsare present for execution of application programsand/or for other purposes. In further examples, computing deviceis configured to synchronize copies of application programsand/or application datafor backup storage at on-premises serversas application programsand/or application data.
602 670 692 602 602 670 692 Embodiments described herein may be implemented in one or more of computing device, network-based server infrastructure, and on-premises servers. For example, in some embodiments, computing deviceis used to implement systems, clients, or devices, or components/subcomponents thereof, disclosed elsewhere herein. In other embodiments, a combination of computing device, network-based server infrastructure, and/or on-premises serversis used to implement the systems, clients, or devices, or components/subcomponents thereof, disclosed elsewhere herein.
620 As used herein, the terms “computer program medium,” “computer-readable medium,” “computer-readable storage medium,” and “computer-readable storage device,” etc., are used to refer to physical hardware media. Examples of such physical hardware media include any hard disk, optical disk, SSD, other physical hardware media such as RAMs, ROMs, flash memory, digital video disks, zip disks, MEMs (microelectronic machine) memory, nanotechnology-based storage devices, and further types of physical/tangible hardware storage media of storage. Such computer-readable media and/or storage media are distinguished from and non-overlapping with communication media, propagating signals, and signals per se. Stated differently, “computer program medium,” “computer-readable medium,” “computer-readable storage medium,” and “computer-readable storage device” do not encompass communication media, propagating signals, and signals per se. Communication media embodies computer-readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave. The term “modulated data signal” means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media includes wireless media such as acoustic, RF, infrared, and other wireless media, as well as wired media. Embodiments are also directed to such communication media that are separate and non-overlapping with embodiments directed to computer-readable storage media.
614 620 660 660 604 602 602 As noted above, computer programs and modules (including application programs) are stored in storage. Such computer programs can also be received via wired interface(s)and/or wireless modem(s)over network. Such computer programs, when executed or loaded by an application, enable computing deviceto implement features of embodiments discussed herein. Accordingly, such computer programs represent controllers of the computing device.
620 Embodiments are also directed to computer program products comprising computer code or instructions stored on any computer-readable medium or computer-readable storage medium. Such computer program products include the physical storage of storageas well as further physical storage types.
Systems, methods, and instrumentalities are described herein related to non-contact authentication for key recovery and platform security provisioning. Access credentials are backed up to and recovered from a user device, such as a smart card, utilized as a secondary root of trust. Automatic, secure backup and storage of user authentication keys, user credentials, crypto tokens, disc encryption recovery key keys, etc. occurs wirelessly onto one or more personal accessories, such as a secure NFC card or a mobile embedded secure component. For example, NFC enabled devices can auto-save secure information in secure storage vaults that are already part of the NFC subsystem when they successfully ‘tap to’ authenticate to access a host computing system. Access to store and retrieve can be further enhanced with geo location presence detection, e.g., using UWB. Credentials can be recovered from secure storage in a user device via a wireless interface, such as NFC or UWB.
A secure information backup/synchronization and recovery service provides an interface for an administrator/user to specify a backup procedure (e.g., indicating what secure key/credential information to backup, when, where, and how) and a recovery procedure to access the backed up information. Information to be backed up to secure storage in a user device may be configured, such as trusted platform module (TPM), disc encryption recovery key, file encryption, and/or account credentials. A user can authenticate during a recovery procedure to retrieve keys backed up on a user device via any configured method, such as password, geofence, third party, etc. Automated backup/synchronization is triggered by one or more configured conditions, such as successful authentication, resulting in automated backup of all configured secure access credentials to one or more designated destinations (e.g., one or more secure user devices or other secure locations). Credential backup synchronization to a user device may be triggered periodically or aperiodically, for example, by successful user authentication during a login procedure. For example, when a user logs in to a host device with an NFC-enabled smart card (SC), designated keys (e.g., disc encryption recovery key) are backed up into a secure component (SE) in the NFC-enabled SC and/or one or more other secure locations indicated to the service.
In one aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a user device, comprises: retrieving a secure token from secure storage in the secure component; wirelessly providing the secure token to a host device performing authentication of a user; in response to authentication of the user by the host device, receiving a user credential synchronization request from the host device; providing a key manifest to the host device in response to the user credential synchronization request; in response a determination the key manifest is unsynchronized based on the absence of one or more user credentials, receiving the one or more absent user credentials; and storing the received one or more absent user credentials in the secure storage to synchronize the user credentials with at least one external user credential store.
According to another aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a host device, comprises: wirelessly receiving a secure token from secure storage in an external secure component; performing authentication of the user based on the secure token; in response to authentication of the user, transmitting a user credential synchronization request to the secure component; receiving a key manifest from the secure component in response to the user credential synchronization request; in response a determination the key manifest is unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the secure component for storage in the secure storage to synchronize the user credentials in the secure component with a user credential store.
According to still another aspect, a method of non-contact authentication for key recovery and platform security provisioning, implemented by a server, comprises: receiving a user credential synchronization request comprising a key manifest for a secure component from a host device in response to a user credential synchronization request provided by the host device to the secure component following authentication of a secure token received by the host device from the secure component; determining whether the key manifest provided by the secure component is synchronized with user credentials in a user credential store managed by the server; and in response a determination the key manifest is unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the host device for transmission to the secure component to synchronize the user credentials in the secure component with the user credential store managed by the server.
In examples, a method may be implemented in at least one computing device. The method may comprise, for example, as described herein.
As described herein by example, a method of performing non-contact authentication for key recovery and platform security provisioning executed by a secure component (e.g., smart card, cell phone), comprises retrieving a secure token from secure storage in the secure component; wirelessly providing the secure token to a host device performing authentication of a user; in response to the user being authenticated by the host device, receiving a user credential synchronization request from the host device; providing a key manifest to the host device in response to the user credential synchronization request; in response a determination the key manifest is unsynchronized based on the absence of one or more user credentials, receiving the one or more absent user credentials; and storing the received one or more absent user credentials in the secure storage to synchronize the user credentials with at least one external user credential store.
In examples, the secure component comprises a smart card.
In examples, the method further comprises providing an additional user credential to the host device performing the user authentication.
In examples, the one or more absent user credentials is determined by the host device. For instance, the absent user credential(s) may be stored at the host device, and thus determined by the host device without resorting to communicating with other devices.
In examples, the one or more absent user credentials is determined by a server and indicated to the host device. For instance, the absent user credential(s) may be stored by or accessible to a server, such as due to the absent user credential(s) being stored/synchronized to a cloud server/storage network for safe keeping. The server may retrieve the absent user credential(s) and provide them to the host device.
In examples, the secure token is provided to the host device by the secure component using near field communication (NFC) or ultra-wideband (UWB) communication.
In examples, the method further comprises receiving a request for user credential recovery; and participating in/providing/supporting/performing a user credential recovery by recovering user credentials from the secure storage according to a user credential recovery configuration.
In examples, the method further comprises receiving the user credential recovery configuration; and indicating multi-factor authentication information for recovery of user credentials. For example, stored keys in the secure storage may be retrieved by authenticating via one or more (e.g., a combination of) methods, such as a (e.g., master) password, a geofence (e.g., geo location presence detection), a third party account, or a third party with an NFC-enabled secure component. In this manner, the stored keys may be more securely stored in the secure storage, and the more stringent authentication of multi-factor authentication may be used to reduce the likelihood of unauthorized users being able to access the stored keys.
As described herein by example, a method of performing non-contact authentication for key recovery and platform security provisioning executed by a host device, comprises wirelessly receiving a secure token from secure storage in an external secure component; performing authentication of a user based on the secure token; in response to the user being authenticated, transmitting a user credential synchronization (e.g., backup) request to the secure component; receiving a key manifest from the secure component in response to the user credential synchronization request; and in response a determination the key manifest is unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the secure component for storage in the secure storage to synchronize the user credentials in the secure component with a user credential store.
In examples, the secure component comprises a smart card.
In examples, the method further comprises receiving an additional user credential for the user authentication.
In examples, the user credential store is managed by at least one of the host device or a server.
In examples, the host device receives the secure token and/or the one or more absent user credentials from the secure component using near field communication (NFC) or ultra-wideband (UWB) communication.
In examples, the method further comprises transmitting a request for user credential recovery to the secure component; and participating in a user credential recovery by recovering user credentials from the secure storage according to a user credential recovery configuration.
In examples, the method further comprises transmitting the user credential recovery configuration to the secure component, wherein the user credential recovery configuration indicates multi-factor authentication information for recovery of user credentials, which may include, for example, retrieving stored keys in the secure storage by authenticating via one or more (e.g., a combination of) approved methods, such as a (e.g., master) password, a geofence (e.g., geo location presence detection), a third party account or a third party with an NFC-enabled secure component.
In examples, the method further comprises transmitting a user credential synchronization configuration to the secure component for responding to the user credential synchronization. In examples, the user credential synchronization configuration indicates what information is synchronized, synchronization conditions (e.g., frequency of update), and synchronization security user credentials (e.g., geolocation, verification of users' identity, such as by UWB).
As described herein by example, a method of performing non-contact authentication for key recovery and platform security provisioning executed by a server, comprises receiving a user credential synchronization request comprising a key manifest for a secure component from a host device in response to a user credential synchronization request provided by the host device to the secure component following authentication of a secure token received by the host device from the secure component; determining whether the key manifest provided by the secure component is synchronized with user credentials in a user credential store managed by the server; and in response a determination the key manifest is unsynchronized based on the absence of one or more user credentials, transmitting the one or more absent user credentials to the host device for transmission to the secure component to synchronize the user credentials in the secure component with the user credential store managed by the server.
In examples, the method further comprises transmitting a request for user credential recovery to the host device; and participating in a user credential recovery by recovering user credentials from the secure component according to a user credential recovery configuration.
In examples, the method further comprises transmitting the user credential recovery configuration to the host device for transmission to the secure component. In examples, the user credential recovery configuration indicates multi-factor authentication information for recovery of keys in the secure storage.
In examples, the method further comprises transmitting a user credential synchronization configuration to the host device for transmission to the secure component for responding to the user credential synchronization. The user credential synchronization configuration indicates what information is synchronized, synchronization conditions (e.g., frequency of update), and synchronization security (e.g., geolocation, verification of users' identity, such as by UWB).
In examples, a computing device and computing system are described herein. A computing device or a computing system may implement any process or method as described herein.
In examples, a computer-readable storage medium is described herein. The computer-readable storage medium has program instructions recorded thereon that, when executed by a processor, implements a method, such as any method described herein.
References in the specification to “one embodiment,” “an embodiment,” “an example embodiment,” etc., indicate that the embodiment described may include a particular feature, structure, or characteristic, but every embodiment may not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
In the discussion, unless otherwise stated, adjectives modifying a condition or relationship characteristic of a feature or features of an implementation of the disclosure, should be understood to mean that the condition or characteristic is defined to within tolerances that are acceptable for operation of the implementation for an application for which it is intended. Furthermore, if the performance of an operation is described herein as being “in response to” one or more factors, it is to be understood that the one or more factors may be regarded as a sole contributing factor for causing the operation to occur or a contributing factor along with one or more additional factors for causing the operation to occur, and that the operation may occur at any time upon or after establishment of the one or more factors. Still further, where “based on” is used to indicate an effect being a result of an indicated cause, it is to be understood that the effect is not required to only result from the indicated cause, but that any number of possible additional causes may also contribute to the effect. Thus, as used herein, the term “based on” should be understood to be equivalent to the term “based at least on.”
Numerous example embodiments have been described above. Any section/subsection headings provided herein are not intended to be limiting. Embodiments are described throughout this document, and any type of embodiment may be included under any section/subsection. Furthermore, embodiments disclosed in any section/subsection may be combined with any other embodiments described in the same section/subsection and/or a different section/subsection in any manner.
Furthermore, example embodiments have been described above with respect to one or more running examples. Such running examples describe one or more particular implementations of the example embodiments; however, embodiments described herein are not limited to these particular implementations.
For example, running examples have been described with respect to malicious activity detectors determining whether compute resource creation operations potentially correspond to malicious activity. However, it is also contemplated herein that malicious activity detectors may be used to determine whether other types of control plane operations potentially correspond to malicious activity.
Several types of impactful operations have been described herein; however, lists of impactful operations may include other operations, such as, but not limited to, accessing enablement operations, creating and/or activating new (or previously-used) user accounts, creating and/or activating new subscriptions, changing attributes of a user or user group, changing multi-factor authentication settings, modifying federation settings, changing data protection (e.g., encryption) settings, elevating another user account's privileges (e.g., via an admin account), retriggering guest invitation e-mails, and/or other operations that impact the cloud-base system, an application associated with the cloud-based system, and/or a user (e.g., a user account) associated with the cloud-based system.
Moreover, according to the described embodiments and techniques, any components of systems, computing devices, servers, device management services, virtual machine provisioners, applications, and/or data stores and their functions may be caused to be activated for operation/performance thereof based on other operations, functions, actions, and/or the like, including initialization, completion, and/or performance of the operations, functions, actions, and/or the like.
In some example embodiments, one or more of the operations of the flowcharts described herein may not be performed. Moreover, operations in addition to or in lieu of the operations of the flowcharts described herein may be performed. Further, in some example embodiments, one or more of the operations of the flowcharts described herein may be performed out of order, in an alternate sequence, or partially (or completely) concurrently with each other or with other operations.
The embodiments described herein and/or any further systems, sub-systems, devices and/or components disclosed herein may be implemented in hardware (e.g., hardware logic/electrical circuitry), or any combination of hardware with software (computer program code configured to be executed in one or more processors or processing devices) and/or firmware.
While various embodiments have been described above, it should be understood that they have been presented by way of example only, and not limitation. It will be apparent to persons skilled in the relevant art that various changes in form and detail can be made therein without departing from the spirit and scope of the embodiments. Thus, the breadth and scope of the embodiments should not be limited by any of the above-described example embodiments, but should be defined only in accordance with the following claims and their equivalents.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
April 5, 2024
August 25, 2026
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.